Back to search
CVE-2015-8025
Published: Nov 10, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.jwz.org/blog/2015/10/xscreensaver-5-34/
x_refsource_CONFIRM
1034052
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2015:2032
vendor-advisory
x_refsource_SUSE
DSA-3438
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20151024 CVE request: xscreensaver aborts when unpluging second monitor cable when asking password
mailing-list
x_refsource_MLIST
https://twitter.com/Thaolia/status/656823859304398848
x_refsource_MISC
USN-2789-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now